GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,201
Erlang
31
GitHub Actions
19
Go
1,986
Maven
5,000+
npm
3,702
NuGet
660
pip
3,328
Pub
11
RubyGems
883
Rust
843
Swift
36
Unreviewed advisories
All unreviewed
5,000+
248 advisories
Filter by severity
In onPackageModified of VoiceInteractionManagerService.java, there is a possible change of...
Moderate
Unreviewed
CVE-2021-0375
was published
May 24, 2022
An issue was discovered in Object First 1.0.7.712. A flaw was found in the Web Service, which...
Moderate
Unreviewed
CVE-2022-44795
was published
Nov 7, 2022
Cryptographically weak PRNG in `utils.generateUUID`
Critical
CVE-2022-36045
was published
for
nodebb
(npm)
Aug 30, 2022
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol...
High
Unreviewed
CVE-2020-27264
was published
May 24, 2022
A vulnerability has been identified in Nucleus NET (All versions), Nucleus RTOS (versions...
Moderate
Unreviewed
CVE-2021-27393
was published
May 24, 2022
Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote...
Moderate
Unreviewed
CVE-2021-25375
was published
May 24, 2022
Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing...
Moderate
Unreviewed
CVE-2021-26909
was published
May 24, 2022
The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and...
Moderate
Unreviewed
CVE-2021-23020
was published
May 24, 2022
Use of Insufficiently Random Values in Apereo CAS
High
CVE-2019-10754
was published
for
org.apereo.cas:cas-server-core-services-api
(Maven)
May 24, 2022
An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow...
High
Unreviewed
CVE-2021-26098
was published
May 24, 2022
In Quest KACE Systems Management Appliance (SMA) through 12.0, predictable token generation...
High
Unreviewed
CVE-2022-29808
was published
Aug 3, 2022
A vulnerability has been found in Morgawr Muon 0.1.1 and classified as problematic. Affected by...
High
Unreviewed
CVE-2019-25089
was published
Dec 27, 2022
A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms...
Moderate
Unreviewed
CVE-2021-3446
was published
May 24, 2022
An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers ...
Critical
Unreviewed
CVE-2020-35685
was published
May 24, 2022
A vulnerability has been identified in LOGO! CMR2020 (All versions < V2.2), LOGO! CMR2040 (All...
Moderate
Unreviewed
CVE-2021-37186
was published
May 24, 2022
Persistent platform private key may not be protected with a random IV leading to a potential “two...
High
Unreviewed
CVE-2021-26322
was published
May 24, 2022
On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then...
High
Unreviewed
CVE-2021-22038
was published
May 24, 2022
Fastly Compute@Edge JS Runtime has fixed random number seed during compilation
High
CVE-2022-39218
was published
for
@fastly/js-compute
(npm)
Sep 20, 2022
DNS NuGet package uses insufficiently random values
Critical
CVE-2021-4248
was published
for
DNS
(NuGet)
Dec 18, 2022
Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017...
High
Unreviewed
CVE-2017-5242
was published
Jan 13, 2023
A misconfiguration of RSA in PingID iOS app prior to 1.19 is vulnerable to pre-computed...
Moderate
Unreviewed
CVE-2021-41994
was published
May 3, 2022
A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed...
Moderate
Unreviewed
CVE-2021-41993
was published
May 3, 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x...
High
Unreviewed
CVE-2022-26071
was published
May 6, 2022
Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are...
Critical
Unreviewed
CVE-2021-34646
was published
May 24, 2022
The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote attackers to...
High
Unreviewed
CVE-2013-6925
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API